Avast SandBox Escape via IOCTL Requests

Posted by Kyriakos Economou on Apr 20

* CVE: CVE-2016-4025
* Vendor: Avast
* Reported by: Kyriakos Economou
* Date of Release: 19/04/2016
* Affected Products: Multiple
* Affected Version: Multiple
* Fixed Version: N/A

Description:
A design flaw in Avast Sandbox allows a potentially harmful program to escape the sandbox and infect the host by
dropping its files out of it and/or by modifying existing legitimate files of any type.

Affected Products:

Avast Internet Security v11.x.x…

Leave a Reply